[bug #68587] Prefer runuser over su

Andreas Metzler <[email protected]> Sun, 2 Aug 2026 05:36:37 -0400 (EDT)
Newsgroups gmane.comp.gnu.findutils.bugs
Message-ID <[email protected]>
--8323329-1714636915-1785663397=:231522
Content-Type: TEXT/plain; CHARSET=utf-8
Content-Transfer-Encoding: QUOTED-PRINTABLE
Content-Disposition: inline

URL:=0A  <https://savannah.gnu.org/bugs/?68587>=0A=0A                 Summa=
ry: Prefer runuser over su=0A                   Group: findutils=0A        =
       Submitter: ametzler=0A               Submitted: So 02 Aug 2026 11:36=
:33 CEST=0A                Category: updatedb=0A                Severity: 3=
 - Normal=0A                Priority: 5 - Normal=0A              Item Group=
: None=0A                  Status: None=0A                 Privacy: Public=
=0A             Assigned to: None=0A         Originator Name:=0A        Ori=
ginator Email:=0A             Open/Closed: Open=0A         Discussion Lock:=
 Unlocked=0A                 Release: 4.11.0=0A           Fixed Release: No=
ne=0A=0A=0A    _______________________________________________________=0A=
=0AFollow-up Comments:=0A=0A=0A--------------------------------------------=
-----------=0ADate: So 02 Aug 2026 11:36:33 CEST   By: Andreas Metzler <ame=
tzler>=0Autil-linux added runuser in 2.23 (April 2013) for exactly the purp=
ose updatdb=0Ais using su for. =0A=0AQuoting su(1)=0A> su is mostly designe=
d for unprivileged users, the recommended=0A> solution for privileged users=
 (e.g.,   scripts   executed by=0A> root)  is  to  use non-set-user-ID comm=
and runuser(1) that does=0A> not  require  authentication and provides sepa=
rate PAM=0A> configuration. If the PAM session is not required at all=0A> t=
hen the recommended solution is to use command setpriv(1).=0A=0AFor Debian =
I am definitely going to switch to fix=0Ahttps://bugs.debian.org/1142935 - =
We are running updated via systemd and are=0Asetting minimal permissions (e=
.g. ProtectSystem=3Dstrict) in the service file.=0AThe su PAM configuration=
 uses pam_wtmpdb/pam_lastlog2 (if installed) but the=0Ainherited systemd sa=
ndboxing prevents mysql write access to the respective=0Adatabases of these=
 PAM modules. Using runuser instead of su fixes this.=0A=0A=0A=0A=0A=0A=0A =
   _______________________________________________________=0AFile Attachmen=
ts:=0A=0AName: POC_runuser.diff               Size: 2,0KiB=0A    <https://f=
ile.savannah.gnu.org/file/POC_runuser.diff?file_id=3D58851>=0A=0A=0A=0A    =
AGPL NOTICE=0A=0AThese attachments are served by Savane. You can download t=
he corresponding=0Asource code of Savane at=0Ahttps://savannah.gnu.org/sour=
ce/savane-c36938be85ff6c1b727bc7dd7fd30e48f9142870.tar.gz=0A=0A    ________=
_______________________________________________=0A=0AReply to this item at:=
=0A=0A  <https://savannah.gnu.org/bugs/?68587>=0A=0A_______________________=
________________________=0ANachricht gesendet =C3=BCber Savannah=0Ahttps://=
savannah.gnu.org/=0A
--8323329-1714636915-1785663397=:231522
Content-Type: APPLICATION/pgp-signature; name=signature.asc

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQQk97aszIMMAvLLwm6qLAuaBUf3TgUCam8PpQAKCRCqLAuaBUf3
Tk47AQDslx9BkuDyZGwDQTZJqfgQnfp5uhxERs5cH0vw0an1pgEAmnNOdp3TCie3
Y5r6Dv348h1j7v1cgO7fajup2vNr2wo=
=b5q0
-----END PGP SIGNATURE-----

--8323329-1714636915-1785663397=:231522--